-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mongodb-14.1-jessie-i386.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-mongodb-14.1-jessie-i386.iso 4a05f2af7a2bda5c23d332269df8a991 $ sha1sum turnkey-mongodb-14.1-jessie-i386.iso 1adc1ca4f9f3ecca05a791a89e17b9d6f79f7fca -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkPyAAoJEIXCXpWhbrlNJmUIAL0Y2bYvgyvL7TmqGz11i9Jw tIg3yYqB/A+n0JCcZqv9rpWiwLwNm054aVeZUFSnH0UpyhDIlO/x6R5zoipMKBo6 KsTHhyCMtjWhakuU2rVzMb6RpLW9fvz6fEOqshFaGnUnIOK8ktK47/U1rw4wlvvA WXeKdpVgaqSxD4/FV+7JLsRhM5ctBHxKp05uyZa0pYYHNtlNwhXLXGph1zfSube9 cNJ+nDtpdGq3VJoVraBqaQu8hLQdfR8npfgLsagLGiXPpudlE66GI89TZtM4DE9l R4TRWFAJZAbfhxBT9DHIT1419xnjVfA3zEXsg482U5opOQ2tIvxyID0YnPse65Y= =iHqy -----END PGP SIGNATURE-----